Key Exchange Mechanism for Bus-Based Communication Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In bus-based communication systems, especially in vehicles, existing methods for ensuring data security and authenticity are resource-intensive and may not meet timing requirements, and preconfigured shared secret keys are cumbersome to change and vulnerable to failure.

Innovation Solution

Implementing a key exchange mechanism using modular exponentiation and Diffie-Hellman principles, allowing nodes to derive a shared secret key on-demand, reducing the number of messages required for key exchange and improving data security, while enabling simpler key configuration and reconfiguration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If preconfigured shared secret keys are used for data security, then data authentication is ensured, but key management becomes cumbersome and vulnerable to failure

Engineering Contradiction:
Improvedata securityVSAvoidkey management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic key generation where secret keys are not static preconfigured values but are generated on-demand through the EKE protocol. Nodes can dynamically establish new shared secrets during runtime, allowing key rotation and reconfiguration without system reconfiguration, thus improving both security and operational flexibility.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system enables nodes to autonomously generate and manage their own secret keys through the EKE protocol without requiring external key management infrastructure. Each node can independently participate in key exchange operations, eliminating the need for centralized key distribution systems and reducing operational complexity.

Inventive Principle:
Principle #25Self-service

2Reliability

If existing data security methods are implemented, then data authentication is provided, but resource consumption increases and timing requirements are not met

Engineering Contradiction:
Improvedata authenticationVSAvoidcommunication speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent combines the key exchange and authentication processes into a single integrated EKE protocol execution. By merging these functions, the system eliminates separate authentication overhead and reduces the total number of communication rounds required, thereby improving communication speed while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The protocol performs preliminary key establishment through modular exponentiation operations that can be computed efficiently in advance. The use of pre-computed values and optimized mathematical operations reduces real-time computational burden, meeting timing requirements for real-time communication systems.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If traditional key exchange protocols are used, then security is maintained, but the number of messages required increases causing bus congestion

Engineering Contradiction:
ImprovesecurityVSAvoidmessage count
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent segments the key exchange process into distinct mathematical operations (modular exponentiation, hash computation) that can be performed with minimal communication. By dividing the security function into computational segments rather than requiring multiple message exchanges, the protocol reduces message count while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The protocol replaces mechanical message-passing-based key exchange with a mathematical computation-based approach using modular exponentiation. This substitution allows nodes to derive shared secrets through local computation rather than through multiple iterative message exchanges, significantly reducing bus traffic while preserving security properties.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11374740B2Controller area network key exchange
Publication Date: 2022.06.28 INFINEON TECHNOLOGIES AG
  • US11374740B2 patent drawing
  • US11374740B2 patent drawing
  • US11374740B2 patent drawing

AI summary

A bus-based communication system, may include a communication bus connecting a plurality of nodes. A first node, of the plurality of nodes, may receive a first message on the communication bus, the first message having been broadcast on the communication bus by a second node of the plurality of nodes. The first message may include a modular exponentiation associated with a private key of the second node. The first node may compute a shared secret key, associated with the plurality of nodes, based at least in part on the modular exponentiation and a private key of the first node.